First published: Tue May 14 2019(Updated: )
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file. The content of the replacement must be derived from the phone's IMEI. The crash occurs upon receiving a message that contains the replaced emoji.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tencent Wechat | <=7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WeChat vulnerability is CVE-2019-11419.
The severity of CVE-2019-11419 is medium with a CVSS score of 5.5.
CVE-2019-11419 is a vulnerability in the WeChat application for Android that allows attackers to cause a denial of service by replacing an emoji file with a crafted .wxgf file.
WeChat versions up to and including 7.0.3 for Android are affected by CVE-2019-11419.
To fix CVE-2019-11419 in WeChat for Android, update to the latest version available.